Win2k runaway stealth process

boa

Senior member
Jul 12, 2001
212
0
0
I built this computer for a friend:
Asus a7v333, 256MB, athlon 1800+, geforce2 gts-v, maxtor 80gb, zoom pci 56k modem, and Win2k.

The problem is that the system now has a runaway process, Winkgw.exe The process is consuming at least 1/3 of the cpu. I cannot identify where/what it is. When I search the disk for Winkgw.exe, it cannot be found. I can start->run Winkgw.exe and it runs!!! I searched for Winkgw.exe, Wink*, Wink*.* and Winkgw*.*

Any idea on how I can find this file?

I had a POS Gateway usb keyboard connected to the computer. It was running the Netropa keyboard software and generating constant osd.exe errors.
I am afraid Winkgw is Win(dows)k(eyboard)g(ate)w(ay).

 

Saltin

Platinum Member
Jul 21, 2001
2,175
0
0
Im pretty sure that's not Klez or EKlern ( the damage dealing virus Klez drops)

I would recommend looking into regedit, and the key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Look and see if your trouble service is listed there. If it is, remove it. It's not an essential service, that's for sure.

EDIT:

I should add that since you can run the exe for the service from the run line, it must be in a folder defined in the PATH. Likely winnt or winnt\system32, but who knows. You can check to make sure no crazy entry was added to your PATH variable in the Environmental Variables of System Properties.

Also, if you find reference to the service in your registry under the key above, it will contain the entire path to the exe.

Remove the exe and remove the reg key, it shouldnt bother you anymore.

 

SoulAssassin

Diamond Member
Feb 1, 2001
6,135
2
0
Originally posted by: Saltin
Im pretty sure that's not Klez or EKlern ( the damage dealing virus Klez drops)

I would recommend looking into regedit, and the key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Look and see if your trouble service is listed there. If it is, remove it. It's not an essential service, that's for sure.

EDIT:

I should add that since you can run the exe for the service from the run line, it must be in a folder defined in the PATH. Likely winnt or winnt\system32, but who knows. You can check to make sure no crazy entry was added to your PATH variable in the Environmental Variables of System Properties.

Also, if you find reference to the service in your registry under the key above, it will contain the entire path to the exe.

Remove the exe and remove the reg key, it shouldnt bother you anymore.

Agreed, might also want to verify that when you're searching that you're including hidden files. If it is in fact a GW keyboard utility I wouldn't imagine that it would be hidden, but hey, I've seen stranger.

 

boa

Senior member
Jul 12, 2001
212
0
0
I checked the PATH. It was:
PATH = C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem

I then checked those directories and could not find the Winkgw file

How would I search for a file that was hidden?

Also, it starts at bootup. Any idea on how to track it?

I'll check the registry tomorrow.

Thank You SO MUCH for the help.
 

Saltin

Platinum Member
Jul 21, 2001
2,175
0
0
Most apps that start up automatically need to make an entry in that registry key, so it's definetly worth a look.
80% of the common viruses do too.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
The only reason I thought it might be klez was because I did a google search and the only things that came up were in another language. I saw klez mentioned, but I couldnt read it

Make sure to get an anti-virus program and keep it up to date, no matter what it is.
 

boa

Senior member
Jul 12, 2001
212
0
0
will do!

Thank You SO MUCH for the help!!!

Actually, thinking back, the virus idea is a very good match. His home computer computer was infected last week! Seems like a little more than just a coincidence.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |